---
title: The Blurred Perimeter | SUMāTO
description: Why the traditional perimeter no longer protects and how to shift to an identity-centered approach. By Andrés Lozada, SUMāTO.
image: https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png
---

[Skip to content](https://sumatogroup.com/en/insights/blog/perimetro-difuso-ciberseguridad#main-content)

- [INSIGHTS](https://sumatogroup.com/en/insights)
- [SUPPORT](https://sumatogroup.com/en/support)
- [CONTACT](https://sumatogroup.com/en/contact)

EN

[Español](https://sumatogroup.com/insights/blog/perimetro-difuso-ciberseguridad) [English](https://sumatogroup.com/en/insights/blog/perimetro-difuso-ciberseguridad)

[![SUMāTO Group — home](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SMT%20-%20LOGO.png?width=40&height=40&name=SMT%20-%20LOGO.png)](https://sumatogroup.com/en)

- [HOME](https://sumatogroup.com/en/)
- About
  
  #### SUMāTO
  
    - [About us→](https://sumatogroup.com/en/about-us)
    - [Terms→](https://sumatogroup.com/en/legal)
    - [Legal→](https://sumatogroup.com/en/legal)
    - [Cookies→](https://sumatogroup.com/en/legal)
    - [Data protection→](https://sumatogroup.com/en/legal)
  
  
  #### METHODOLOGIES
  
    - [Design Thinking→](https://sumatogroup.com/en/methodologies#design-thinking)
    - [Lean Startup→](https://sumatogroup.com/en/methodologies#lean-startup)
    - [PMI→](https://sumatogroup.com/en/methodologies#pmi)
    - [Scrum→](https://sumatogroup.com/en/methodologies#scrum)
  
  
  #### Vendors
  
    - [AWS→](https://sumatogroup.com/en/vendors#aws)
    - [Cisco→](https://sumatogroup.com/en/vendors#cisco)
    - [Dahua→](https://sumatogroup.com/en/vendors#dahua)
    - [Fortinet→](https://sumatogroup.com/en/vendors#fortinet)
    - [Huawei→](https://sumatogroup.com/en/vendors#huawei)
    - [Microsoft→](https://sumatogroup.com/en/vendors#microsoft)
    - [OCI→](https://sumatogroup.com/en/vendors#oci)
    - [Panduit→](https://sumatogroup.com/en/vendors#panduit)
- Capabilities
  
  #### TECHNOLOGY
  
    - [Artificial Intelligence→](https://sumatogroup.com/en/artificial-intelligence)
    - [Data Analytics→](https://sumatogroup.com/en/data-analytics)
    - [Automation→](https://sumatogroup.com/en/automation-rpa)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity)
    - [Cloud→](https://sumatogroup.com/en/cloud)
  
  
  #### SEGMENTS
  
    - [SMB→](https://sumatogroup.com/en/smb)
    - [Enterprise→](https://sumatogroup.com/en/enterprise)
    - [Government→](https://sumatogroup.com/en/government)
- Consulting
  
  #### Assessments
  
    - [AI Readiness→](https://sumatogroup.com/en/ai-readiness-assessment)
    - [Analytics→](https://sumatogroup.com/en/data-analytics-maturity-assessment)
    - [Cloud→](https://sumatogroup.com/en/cloud-readiness-assessment)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity-assessment)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-assessment)
    - [IT Maturity→](https://sumatogroup.com/en/it-maturity-assessment)
    - [IT Strategy→](https://sumatogroup.com/en/technology-strategy-assessment)
    - [Process Automation→](https://sumatogroup.com/en/process-automation-assessment)
  
  
  #### Consulting & Architecture
  
    - [AI First→](https://sumatogroup.com/en/ai-first)
    - [BCP→](https://sumatogroup.com/en/business-continuity-plan)
    - [DRP→](https://sumatogroup.com/en/disaster-recovery-plan)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-togaf)
    - [Enterprise Transformation→](https://sumatogroup.com/en/enterprise-transformation)
    - [IT Strategic Plan→](https://sumatogroup.com/en/it-strategic-plan)
    - [Strategic Consulting→](https://sumatogroup.com/en/strategic-consulting)
- Operations
  
  #### INFRASTRUCTURE
  
    - [Data Center→](https://sumatogroup.com/en/data-center)
    - [Managed Services→](https://sumatogroup.com/en/managed-services)
    - [VDI→](https://sumatogroup.com/en/vdi)
    - [Intelligent Video Surveillance→](https://sumatogroup.com/en/video-surveillance)
  
  
  #### SECURITY
  
    - [NOC→](https://sumatogroup.com/en/noc)
    - [SOC→](https://sumatogroup.com/en/soc)
  
  
  #### USERS
  
    - [Modern Desktop→](https://sumatogroup.com/en/modern-desktop)
    - [Help Desk→](https://sumatogroup.com/en/help-desk)
- Industries
  
  Industries
  
    - [Banking & Finance→](https://sumatogroup.com/en/banking-finance)
    - [Insurance→](https://sumatogroup.com/en/insurance)
    - [Government→](https://sumatogroup.com/en/government)
    - [Healthcare→](https://sumatogroup.com/en/healthcare)
    - [Telecommunications→](https://sumatogroup.com/en/telecommunications)
    - [Retail & Consumer→](https://sumatogroup.com/en/retail)
    - [Manufacturing→](https://sumatogroup.com/en/manufacturing)
    - [Energy, Oil & Gas→](https://sumatogroup.com/en/energy-oil-gas)
    - [Education→](https://sumatogroup.com/en/education)
    - [Logistics & Transportation→](https://sumatogroup.com/en/logistics-transport)
    - [Legal Services→](https://sumatogroup.com/en/legal-services)
    - [Engineering & Construction→](https://sumatogroup.com/en/engineering-construction)
- Resources
  
  #### CONTENT
  
    - [Blog→](https://sumatogroup.com/en/insights)
    - [Use cases→](https://sumatogroup.com/en/use-cases)
  
  
  #### EVENTS
  
    - [Webinars→](https://sumatogroup.com/en/webinars)

EN

[Español](https://sumatogroup.com/insights/blog/perimetro-difuso-ciberseguridad) [English](https://sumatogroup.com/en/insights/blog/perimetro-difuso-ciberseguridad)

Search

- There are no suggestions because the search field is empty.

[Ciberseguridad](https://sumatogroup.com/en/insights/tag/ciberseguridad)

# The Blurred Perimeter: Cybersecurity in Remote Work

[Andrés Lozada](https://sumatogroup.com/en/insights/author/andres-lozada) · May 19, 2020, 8:00:00 AM · 7 min read

For years, corporate security was imagined as a castle: a sturdy wall, a well-guarded moat, and a single point of entry. As long as the equipment, the data, and the people stayed inside the office, that model was enough. But when, within a matter of weeks, employees began connecting from the dining room table, over home networks and shared devices, the wall simply ceased to exist. The perimeter became blurred, and with it, much of the certainty on which your organization's defense rested.

**In brief:** The traditional network perimeter no longer defines what needs protecting, because work is done outside it. The attack surface grew with home devices, overloaded VPNs, and more sophisticated phishing campaigns. The answer is not to build higher walls, but to move security's center of gravity from the network toward identity and continuous monitoring.

## Why the traditional perimeter stopped protecting you

The classic security model starts from a premise that is untenable today: that everything inside the corporate network is trustworthy and everything outside is suspicious. That assumption worked when the perimeter firewall coincided with the company's physical walls. With remote work, most legitimate traffic originates precisely outside that edge, while an attacker, once they obtain valid credentials, automatically lands on the "trusted" side.

The underlying problem is conceptual. When network location stops being a reliable indicator of trust, continuing to base controls on the IP address or the network segment is like guarding a door no one uses anymore. The most relevant risks today are:

- **Implicit trust:** whoever manages to get into the network gains broad lateral access, with few internal barriers.
- **Devices out of control:** personal equipment and home networks without patches, without encryption, and shared with other members of the household.
- **Reduced visibility:** traffic that no longer passes through the office escapes centralized inspection tools.

## The growth of the attack surface

Each new connection point is a new potential door. By distributing employees, the organization multiplies the places where an attacker can try to get in, and reduces its ability to monitor them all with the same depth. Three fronts concentrate most of this expansion.

### Home devices and networks

The corporate laptop that once lived behind several layers of defense now shares a router with game consoles, smart TVs, and third-party devices. If the machine is not well managed, with an encrypted disk, up-to-date antivirus, and a hardened configuration, it becomes the weakest link in the entire chain.

### VPN under pressure

The VPN was the fast, reasonable answer for extending the corporate network into homes. But used as the sole defense it has important limits: it concentrates all traffic at one point, grants broad access once the connection is established, and, if credentials are compromised, it opens the entire network. The VPN protects the tunnel, not necessarily what travels through it nor who is at the other end.

### Phishing and social engineering

Away from the office, without the ability to turn and ask a colleague whether an email is legitimate, people are more vulnerable to deception. Phishing campaigns have become more targeted, imitating internal communications, requests from management, or notices from everyday services. The goal is almost always the same: steal credentials to get in as a legitimate user.

## The shift toward identity as the new perimeter

If the network no longer defines the boundary of trust, what does? The answer gaining ground is clear: identity. When you can no longer trust the place someone connects from, what matters is to rigorously verify who they are, with what device, and which resource they are trying to access, every time.

This approach, a precursor to what the industry is beginning to call Zero Trust, boils down to a simple principle: never trust by default, always verify. In practice, it means building security around identity with measures such as:

- **Multi-factor authentication (MFA):** the password alone is no longer enough; a second factor drastically reduces the impact of a stolen credential.
- **Least-privilege access:** each user accesses only what they need for their work, not the entire network.
- **Contextual verification:** evaluating signals such as the device, the time, or the geolocation to grant, limit, or require additional verification.
- **Centralized identity management:** a single point to create, adjust, and revoke access immediately.

Adopting this model does not require replacing all your infrastructure overnight. It is a shift in priorities: putting identity at the center and advancing in layers, starting with the most critical access. You can explore how to approach it in a structured way in our [cybersecurity](https://sumatogroup.com/ciberseguridad) practice.

## Continuous monitoring: seeing what happens beyond the wall

Verifying identity at the moment of access is necessary, but not sufficient. A legitimate credential can be used by the wrong person, and a trusted device can be compromised after connecting. That is why the second pillar of this new approach is visibility: knowing, at all times, what is happening.

Continuous monitoring seeks to detect the anomalous before it becomes an incident. For an organization with distributed teams, this means paying attention to signals such as:

- **Unusual behavior:** access at atypical hours, from impossible locations, or at data volumes outside the norm.
- **Event correlation:** joining identity, device, and application logs to see the full picture, not isolated pieces.
- **Timely response:** having the ability to act, isolate a machine, or revoke access, in minutes and not in days.

Sustaining this vigilance around the clock is hard to achieve with isolated efforts. This is where a Security Operations Center adds value, by combining technology, processes, and analysts dedicated to detecting and responding continuously. If your organization does not yet have that capability, it is worth learning how a modern [SOC](https://sumatogroup.com/soc) operates.

## How to start redrawing your perimeter

The transition to identity-centered security is a journey, not a switch. These initial steps offer tangible progress without paralyzing the operation:

- **Enable MFA** on all critical access, starting with email, administrative tools, and financial applications.
- **Inventory your devices** and make sure the equipment accessing corporate resources meets minimum security requirements.
- **Review privileges** and remove broad access that is no longer justified.
- **Establish visibility** over identity and access events, even incrementally.
- **Train your teams** to recognize phishing attempts, their first and best line of defense.

## Frequently asked questions

**Is the VPN useless now?** It still serves a purpose, but it should not be your only defense. The VPN encrypts traffic, which is valuable, but it does not continuously verify who is at the other end nor limit access once the connection is established. It is best complemented with strong authentication and least-privilege controls.

**What exactly is the Zero Trust approach?** It is a security model that eliminates implicit trust based on network location. Its principle is "never trust, always verify": every access request is validated according to identity, device, and context, no matter where it originates.

**Can a mid-sized company adopt this model?** Yes. It does not require replacing all the infrastructure at once. You advance in layers, prioritizing the most critical access and data. Measures such as MFA and privilege review offer a high return on a reasonable investment.

**Why do I need monitoring if I already verify identity?** Because the initial verification does not guarantee that nothing changes afterward. A legitimate session can be hijacked or a device compromised after connecting. Continuous monitoring detects those anomalous behaviors in time.

## The first step

The blurred perimeter is not a passing problem: it is the new reality of work. The organizations that thrive will be those that stop defending a nonexistent wall and start protecting what truly matters, the identities, the data, and the ability to see what is happening. At SUMāTO we support LATAM companies through that transition, with a pragmatic, staged approach. If you would like to assess where your organization stands today and where to begin, [let's talk](https://sumatogroup.com/contacto).

Continue reading

- [SOC: 24/7 Watch When Everything Is Distributed](https://sumatogroup.com/en/insights/blog/soc-vigilancia-distribuida)
- [Software Supply Chain Cybersecurity](https://sumatogroup.com/en/insights/blog/ciberseguridad-cadena-suministro)

Next step

Do you know where you are exposed today, and what to remediate first?

[Cybersecurity Assessment →](https://sumatogroup.com/en/cybersecurity-assessment)

[Ciberseguridad](https://sumatogroup.com/en/insights/tag/ciberseguridad)

![Andrés Lozada](https://sumatogroup.com/hs-fs/hubfs/SPEAKERS/AL.jpeg?width=56&height=56&name=AL.jpeg)

Andrés Lozada May 19, 2020, 8:00:00 AM 

[LinkedIn](https://www.linkedin.com/in/andreslozada/)

### Explore more from SUMāTO

[Enterprise AI](https://sumatogroup.com/en/artificial-intelligence) [Enterprise Transformation](https://sumatogroup.com/en/enterprise-transformation) [Strategic Consulting](https://sumatogroup.com/en/strategic-consulting) [AI Agent](https://sumatogroup.com/en/artificial-intelligence) [AI Contact Center](https://sumatogroup.com/en/artificial-intelligence) [Cybersecurity](https://sumatogroup.com/en/cybersecurity)

### Related Posts

#### [MOVEit: When a Zero-Day Exposes Thousands of Organizations](https://sumatogroup.com/en/insights/blog/moveit-dia-cero)

In the final weeks of May and throughout June 2023, thousands of organizations around the world discovered that a tool they used every day for...

#### [Supply Chain Attacks: When Risk Enters Through a Vendor](https://sumatogroup.com/en/insights/blog/ataques-cadena-suministro)

Imagine your organization did everything right: you patched your servers, trained your team, bought reputable security tools. And yet, one fine day,...

#### [Post-quantum: prepare today for tomorrow's encryption](https://sumatogroup.com/en/insights/blog/post-quantum-cifrado)

There is an uncomfortable truth that few technology committees in LATAM dare to put on the table: most of the encryption protecting your organization...

![SUMāTO](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png?width=200&height=100&name=SUM%C4%81TO%20%7C%20LOGO%201000x500.png)

Strategic technology planning consultants.

AI, Analytics, Cloud and Cybersecurity

<https://www.linkedin.com/company/sumatogroup> <https://www.youtube.com/@sumatogroup>

## Navigation

[Home](https://sumatogroup.com/en) [Capabilities](https://sumatogroup.com/en/artificial-intelligence) [Consulting](https://sumatogroup.com/en/strategic-consulting) [Operations](https://sumatogroup.com/en/managed-services) [Industries](https://sumatogroup.com/en/banking-finance) [Resources](https://sumatogroup.com/en/insights)

## SUMāTO

[About](https://sumatogroup.com/en/about-us) [Terms](https://sumatogroup.com/en/legal#terminos) [Legal & Privacy](https://sumatogroup.com/en/legal) [Data protection](https://sumatogroup.com/en/legal)

Cookies

## [Contact](https://sumatogroup.com/en/contact)

[sales@sumatogroup.com](mailto:sales@sumatogroup.com)

Mexico HQ

Mexico City, Mexico

[+52 55 8897 5791](tel:+525588975791)

Bogotá

Bogotá, Colombia

[+57 601 724 5059](tel:+576017245059)

© 2026 SUMāTO Group. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrés Lozada",
    "url" : "https://sumatogroup.com/en/insights/author/andres-lozada"
  },
  "dateModified" : "2026-07-09T19:22:36.897Z",
  "datePublished" : "2020-05-19T13:00:00.000Z",
  "headline" : "The Blurred Perimeter | SUMāTO",
  "mainEntityOfPage" : {
    "@id" : "https://sumatogroup.com/en/insights/blog/perimetro-difuso-ciberseguridad",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://sumatogroup.com/hubfs/BRANDING/Logo_SUMATO_Original%20-%201000x500.png"
    },
    "name" : "SUMāTO Group"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "It still serves a purpose, but it should not be your only defense. The VPN encrypts traffic, which is valuable, but it does not continuously verify who is at the other end nor limit access once the connection is established. It is best complemented with strong authentication and least-privilege controls."
    },
    "name" : "Is the VPN useless now?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "It is a security model that eliminates implicit trust based on network location. Its principle is \"never trust, always verify\": every access request is validated according to identity, device, and context, no matter where it originates."
    },
    "name" : "What exactly is the Zero Trust approach?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. It does not require replacing all the infrastructure at once. You advance in layers, prioritizing the most critical access and data. Measures such as MFA and privilege review offer a high return on a reasonable investment."
    },
    "name" : "Can a mid-sized company adopt this model?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Because the initial verification does not guarantee that nothing changes afterward. A legitimate session can be hijacked or a device compromised after connecting. Continuous monitoring detects those anomalous behaviors in time."
    },
    "name" : "Why do I need monitoring if I already verify identity?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "MX",
    "addressLocality" : "Huixquilucan",
    "addressRegion" : "Estado de México",
    "postalCode" : "52787",
    "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
  },
  "alternateName" : [ "SUMāTO Group", "SUMATO Group", "Sumato Group", "SUMATO", "SUMaTO", "SUMaTO Group", "SUMTO", "SUMTO Group" ],
  "areaServed" : [ {
    "@type" : "Country",
    "name" : "México"
  }, {
    "@type" : "Country",
    "name" : "Colombia"
  }, {
    "@type" : "Place",
    "name" : "Latinoamérica"
  } ],
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "Latinoamérica",
    "availableLanguage" : [ "es", "en" ],
    "contactType" : "sales",
    "email" : "sales@sumatogroup.com"
  },
  "description" : "SUMāTO is a Latin American technology consulting and integration firm founded in 2016, with a presence in Mexico and Colombia. It designs, implements and operates artificial intelligence, data analytics, automation, cybersecurity and cloud on the systems a client already runs, under governance frameworks such as NIST AI RMF and ISO/IEC 42001.",
  "foundingDate" : "2016",
  "knowsAbout" : [ "Inteligencia Artificial", "IA Generativa", "Agentes de IA", "Analítica de Datos", "Big Data", "Automatización de Procesos (RPA)", "Ciberseguridad", "Computación en la Nube", "Continuidad del Negocio y Recuperación ante Desastres", "Arquitectura Empresarial", "Transformación Digital" ],
  "legalName" : "SUMāTO Group",
  "location" : [ {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "MX",
      "addressLocality" : "Huixquilucan",
      "addressRegion" : "Estado de México",
      "postalCode" : "52787",
      "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
    },
    "name" : "SUMāTO MX",
    "telephone" : "+52 55 8897 5791"
  }, {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "CO",
      "addressLocality" : "Bogotá",
      "streetAddress" : "Cra. 45 # 103-34, Of. 202"
    },
    "name" : "SUMāTO CO",
    "telephone" : "+57 601 724 5059"
  } ],
  "logo" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png",
    "width" : 1000
  },
  "name" : "SUMāTO",
  "sameAs" : [ "https://www.linkedin.com/company/sumatogroup", "https://www.youtube.com/@sumatogroup", "https://torre.ai/teams/SUMaTOGroup", "https://www.cbinsights.com/company/sumto-group", "https://elioplus.com/profiles/channel-partners/57295/sumato-group" ],
  "telephone" : "+52 55 8897 5791",
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#website",
  "@type" : "WebSite",
  "description" : "Technology consulting in AI, data, automation, cybersecurity and cloud across Latin America.",
  "inLanguage" : "en",
  "name" : "SUMāTO",
  "publisher" : {
    "@id" : "https://sumatogroup.com/#organization"
  },
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en/insights/blog/perimetro-difuso-ciberseguridad",
    "name" : "The Blurred Perimeter: Cybersecurity in Remote Work",
    "position" : 2
  } ]
}
```